Solana Foundation's Chief Security Officer warns that AI-powered social engineering and fake identities pose greater threats than smart contract exploits.
Regulation & Gov ·
Michael Coates, the newly appointed Chief Information Security Officer at the Solana Foundation, has warned that AI-powered social engineering and fake identities represent the next major threat vector in crypto security, rather than traditional smart contract vulnerabilities. Coates, who previously held CISO roles at Twitter and Mozilla, contends that many recent major security breaches in crypto ecosystems have originated from compromised credentials and AI-generated scams rather than on-chain exploits, and notes that attackers are increasingly targeting people instead of protocols.
As AI capabilities advance, social engineering attacks will become significantly harder to defend against through conventional means, Coates explained. He highlighted the potential for full spoofed voice calls and deepfakes, stating that such tactics will likely scale widely. To mitigate this shift, crypto projects must adopt multi-layered security controls that protect users even when social engineering succeeds—a departure from traditional approaches that assume users will remain vigilant.
Coates also emphasized that the crypto industry must broaden its security posture beyond smart contract audits, requiring practices comparable to Web2 companies while addressing blockchain-specific risks. On longer-term threats, the Solana Foundation is evaluating post-quantum cryptography strategies in anticipation of quantum computing's eventual arrival, though the timing of such threats remains uncertain.